The "No New AI Law" Gamble: Why India’s DPDP Rules 2025 Just Became Your De Facto AI Playbook
For the past two years, technology lawyers and in-house counsel across India have been holding their breath, waiting for the Ministry of Electronics and Information Technology (MeitY) to drop a bespoke, overarching Artificial Intelligence Act. We exp...
For the past two years, technology lawyers and in-house counsel across India have been holding their breath, waiting for the Ministry of Electronics and Information Technology (MeitY) to drop a bespoke, overarching Artificial Intelligence Act. We expected algorithmic audits, mandatory AI disclosures, and a new regulatory body. Instead, the government has delivered a stark reality check: there is no AI silver bullet coming.
According to the latest policy signals in early 2026, the Centre has made it abundantly clear that it prefers to govern AI through existing frameworks—specifically, the Digital Personal Data Protection (DPDP) Act, 2023 and India’s legacy Intellectual Property (IP) regime. Unless "absolutely necessary," a standalone AI law is off the table.
This is a seismic shift in regulatory strategy. It means the legal ambiguities surrounding AI are no longer a future problem for a future statute. They are a present-day compliance crisis that must be solved using the tools we already have. If you are advising tech startups, ad-tech platforms, or enterprises integrating Generative AI, your practice just fundamentally changed.
The DPDP Rules 2025: The Teeth Have Arrived
The operationalization of the DPDP Act through the newly notified Digital Personal Data Protection Rules, 2025 (issued under Section 40 of the Act) is the most consequential development for Indian tech law this decade. With staggered commencement dates now in effect, the DPDP framework has officially transitioned from a theoretical legislative milestone to an aggressive compliance regime.
For AI developers, data is the raw material. Under the new Rules, scraping the Indian web to train Large Language Models (LLMs) is no longer just an IP risk; it is a massive privacy liability. The moment an AI model ingests personally identifiable information (PII) without explicit consent, the developer becomes a non-compliant Data Fiduciary under Section 8 of the DPDP Act.
"We are witnessing the death of the 'move fast and break things' era in Indian tech. The DPDP Rules 2025 force a shift from reactive legal firefighting to proactive, privacy-by-design engineering."
Consent is Governance, Not a Checkbox
One of the most profound shifts highlighted in recent legal discourse is the reinterpretation of "consent." As thoroughly dissected in recent SCC Online analyses, Sections 5 and 6 of the DPDP Act fundamentally destroy the traditional "clickwrap" model.
Under the new regime, consent must be free, specific, informed, unconditional, and unambiguous. For practicing lawyers, this means:
1. The Burden of Proof has Shifted: In the event of a dispute or a data breach, the Data Fiduciary bears the absolute burden of proving that valid notice was given and lawful consent was obtained. You can no longer rely on a user's failure to opt-out.
2. The Right to Withdraw: Section 6(4) mandates that withdrawing consent must be as easy as giving it. If an Indian user withdraws consent, their data must be purged. But how do you "unlearn" or delete a specific Data Principal's information once it has been baked into the weights of an AI neural network? The technology barely exists, yet the legal obligation is now live.
Shoehorning AI into the Copyright Act, 1957
By refusing to enact an AI-specific law, the government is forcing IP lawyers to stretch the Copyright Act, 1957 to its breaking point. When an AI company scrapes copyrighted articles, artwork, or code to train its models, is it infringement, or is it protected under the "fair dealing" exceptions of Section 52?
Currently, Indian courts are left to navigate this vacuum. Without a statutory safe harbor for Text and Data Mining (TDM)—which jurisdictions like the EU and Japan have expressly addressed—Indian AI startups are operating in a zone of extreme IP peril. As counsel, you must advise clients that relying on a broad interpretation of "fair dealing" for commercial AI training in India is a massive, unquantified financial risk.
What This Means for Your Practice Today
The government's strategy of layering AI governance onto the DPDP Act and IP laws dictates a clear, immediate action plan for legal practitioners:
Revise Data Processing Agreements (DPAs): Your boilerplate DPAs are obsolete. They must now explicitly address the DPDP Rules 2025, particularly regarding vendor data transfers, strict retention/deletion timelines, and incident response protocols.
Audit AI Training Pipelines: You must sit down with your client's engineering teams. If they are training models, you need a documented chain of title for the dataset. Is there copyrighted material? Was PII scrubbed? If not, the model is legally toxic.
Redesign Consent Architectures: Work with UI/UX teams to eliminate dark patterns. Notice mechanisms (Section 5) must be localized, clear, and require affirmative action.
The message from the Centre is clear: do not wait for a shiny new AI Act to tell you what to do. The regulatory framework is already here. It is messy, it is complex, and it requires cross-disciplinary mastery of privacy and intellectual property. Lawyers who adapt to this reality will thrive; those who wait for a standalone AI law will be left defending indefensible compliance failures.
Tags
Published by AnrakLegal AI